A sophisticated supply chain attack involving the malicious 'indexed-btree' NPM package has reached millions of downloads by mimicking a legitimate utility.
A malicious npm package mimicking a legitimate utility has been found hiding its malware loader in runtime code to bypass new npm security controls.
The ClickFix campaign has pivoted from OS-level commands to browser-based JavaScript injection, exploiting Google Sheets to steal cryptocurrency from unsuspecting users.